Skip to main content

Framework

Digital Operational Resilience Act (DORA)

Senior practitioner-led DORA compliance implementation for UK financial services entities operating in the EU and UK ICT third-party providers serving EU financial firms. Applicable from 17 January 2025.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. DORA is not a service Goldline delivers as a standalone product.

DORA applies to EU financial services and their supply chain. It references ISO 27001 as a relevant standard for ICT risk management. Organisations in scope of DORA typically implement ISO 27001 as the foundational management system that operationalises DORA requirements, with DORA-specific extensions layered on top.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is DORA?

The Digital Operational Resilience Act (DORA), formally EU Regulation 2022/2554, is a European Union regulation establishing a unified framework for digital operational resilience across the EU financial services sector. DORA became applicable on 17 January 2025 following a two-year transition period. The regulation aims to ensure that financial entities operating in the EU can withstand, respond to, and recover from information and communication technology disruptions and threats.

DORA is structured around five core pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and information and intelligence sharing. Together these pillars create a comprehensive operational resilience framework that affected entities must implement, maintain, and demonstrate to competent authorities.

DORA is enforced by national competent authorities including the FCA, the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA). Non-compliance carries administrative penalties, regulatory enforcement, and reputational consequences for affected financial entities and their critical ICT providers.

DORA operates as lex specialis to the NIS 2 Directive for financial entities. Where DORA addresses ICT risk management, incident reporting, operational resilience testing, information sharing, and ICT third-party risk, DORA provisions apply instead of equivalent NIS 2 provisions. Member States do not apply NIS 2 cybersecurity risk-management and reporting obligations to financial entities covered by DORA.

Specific DORA articles your organisation must address

  • Article 6 to 16: ICT risk management framework requirements
  • Article 17 to 23: ICT-related incident reporting timelines and classification
  • Article 24 to 27: Digital operational resilience testing including Threat-Led Penetration Testing (TLPT) for significant financial entities
  • Article 28 to 30: ICT third-party risk management including contractual provisions and subcontracting controls
  • Article 41: Critical ICT third-party service provider oversight framework
  • Article 45: Voluntary information and intelligence sharing arrangements

Who needs to comply with DORA?

DORA applies directly to two categories of organisation. The framework reaches a third category indirectly through contract flowdown from regulated entities.

EU financial entities

DORA applies directly to financial entities operating within the EU. Credit institutions, payment institutions, investment firms, insurance undertakings, crypto-asset service providers, crowdfunding platforms, investment fund managers, central securities depositories, central counterparties, credit rating agencies, and statutory auditors (limited scope).

ICT third-party service providers

DORA applies directly to ICT third-party service providers designated as "critical" by the European Supervisory Authorities, and applies contractually through DORA-compliant terms to all ICT third-party service providers serving financial entities.

Indirect via contract flowdown

UK ICT third-party providers serving EU financial entities face DORA compliance requirements through contractual flowdown. UK financial entities operating cross-border into the EU fall under DORA directly. UK-only financial entities face DORA-equivalent expectations through FCA Operational Resilience (PS21/3), the Critical Third Parties regime under FSMA 2023, and the forthcoming Cyber Security and Resilience Bill.

DORA's five pillars in detail

DORA structures its operational resilience requirements around five interconnected pillars. Compliance requires implementation across all five.

Pillar 1: ICT risk management

Financial entities must establish a comprehensive ICT risk management framework integrated into broader enterprise risk governance. The framework must include ICT risk identification, classification, monitoring, mitigation, business impact analysis, and continuous improvement. Senior management and the management body hold direct accountability for ICT risk management oversight. ICT systems supporting critical or important functions face enhanced controls including continuous risk assessment, vulnerability management, and resilience testing.

Pillar 2: ICT-related incident reporting

Financial entities must implement processes for detecting, classifying, and reporting major ICT-related incidents to competent authorities. Reporting timelines are prescriptive: initial notification within hours, intermediate reports as the incident evolves, and final reports following resolution. The classification framework considers materiality factors including number of affected clients, geographic spread, data losses, and reputational impact. Incident reporting templates and timelines are specified in DORA Implementing Technical Standards (ITS).

Pillar 3: Digital operational resilience testing

Financial entities must conduct regular operational resilience testing proportionate to size, complexity, and risk profile. Testing includes vulnerability assessments, scenario-based testing, performance testing, and source code reviews. Significant financial entities (defined by ITS thresholds) must additionally undertake Threat-Led Penetration Testing (TLPT) every three years, conducted by external testers meeting DORA-specified competency requirements. TLPT must follow the TIBER-EU framework or an equivalent recognised methodology.

Pillar 4: ICT third-party risk management

Financial entities must manage ICT third-party risk through a structured framework covering due diligence prior to contracting, contractual provisions specified by DORA Articles 28 and 30, ongoing monitoring, and exit strategies. ICT third-party service providers supporting critical or important functions must accept DORA-compliant contract terms covering subcontracting restrictions, audit rights, data location specifications, and exit support obligations. Designated 'critical' ICT third-party providers face direct oversight by European Supervisory Authorities.

Pillar 5: Information and intelligence sharing

DORA encourages financial entities to participate in voluntary cyber threat intelligence sharing arrangements with other financial entities. While not mandatory, intelligence sharing supports sector-wide resilience and is considered favourable by competent authorities when assessing operational resilience maturity. Financial entities establishing intelligence sharing arrangements must operate them within data protection and competition law constraints.

METHODOLOGY

How Goldline delivers DORA implementation

The Goldline Method applied to DORA compliance. Six phases from regulatory scoping through ongoing operational resilience. Calibrated to your DORA applicability (direct EU financial entity, UK financial entity operating in the EU, or UK ICT provider with EU financial entity flowdown).

  1. 01

    Phase 1

    Scope and applicability assessment

    Senior practitioner-led determination of DORA applicability across your business lines and ICT estate. Direct application versus contractual flowdown identified. Critical ICT services in scope mapped. Existing operational resilience programme alignment with DORA five pillars assessed.

    • Applicability assessment
    • Scope memorandum
    • Gap baseline
  2. 02

    Phase 2

    ICT risk management framework

    DORA Article 6 ICT risk management framework designed and implemented. Integrated into enterprise risk governance. Senior management accountability formalised. ICT systems supporting critical or important functions identified with enhanced control mapping.

    • Risk framework
    • Governance structure
    • Critical function register
  3. 03

    Phase 3

    Incident reporting and detection

    DORA Article 17-23 ICT-related incident classification and reporting process implemented. Materiality thresholds aligned to ITS specifications. Detection, classification, and reporting workflow built with appropriate timelines for initial, intermediate, and final reports to competent authorities.

    • Incident process
    • Classification matrix
    • Reporting workflow
  4. 04

    Phase 4

    Digital operational resilience testing

    DORA Article 24-27 testing programme established. Vulnerability assessments, scenario-based testing, and performance testing scoped. For significant financial entities, Threat-Led Penetration Testing methodology aligned to TIBER-EU framework prepared with external tester procurement.

    • Testing programme
    • TLPT scoping
    • Scenario library
  5. 05

    Phase 5

    ICT third-party risk management

    DORA Article 28-30 third-party risk framework implemented. Vendor due diligence, contractual provisions, ongoing monitoring, and exit strategies established. DORA-compliant contract terms drafted for ICT service providers supporting critical or important functions. Subcontracting controls per Article 30(2) configured.

    • Vendor framework
    • Contract terms
    • Exit strategies
  6. 06

    Phase 6

    Information sharing and oversight readiness

    DORA Article 45 information sharing arrangements evaluated and implemented where appropriate. Competent authority oversight readiness validated. Documentation prepared to demonstrate compliance to FCA, EBA, EIOPA, or ESMA on demand. Ongoing operational resilience maturity embedded.

    • Sharing arrangements
    • Oversight pack
    • Ongoing maturity

DORA implementation pathways

Goldline supports DORA compliance through three engagement pathways calibrated to organisational scope and ongoing advisory needs.

Compliance-as-a-Service

UK SaaS scaleups providing services to EU financial entities, facing DORA-compliant contract terms flowdown. Compliance-as-a-Service includes ongoing DORA posture management, third-party risk evidence preparation, contract response support, and integration with the client's existing compliance programme.

Discuss your DORA programme

Project-based DORA implementation engagement

EU and UK financial entities directly subject to DORA. Senior practitioner founder-led project engagement scoped to DORA's five pillars with phased delivery, integrated with existing ISO 27001 or operational resilience programmes where applicable. Engagement scope, timeline, and commercial structure established during qualified discovery.

Book the Free Diagnostic

Strategic governance retainer

Complex multi-jurisdictional financial entities operating across UK and EU with DORA, FCA Operational Resilience, NIS 2, and adjacent regulatory exposure. Ongoing senior practitioner advisory retainer covering DORA alongside broader operational resilience and cyber governance obligations.

Book the Free Diagnostic

Frameworks DORA integrates with

DORA implementation typically intersects with adjacent regulatory and certification frameworks. Goldline calibrates DORA delivery to leverage existing control evidence and compliance investment where adjacencies exist.

  • ISO 27001 ISMS

    Provides foundational information security control framework that addresses substantial portions of DORA Pillar 1 (ICT risk management) requirements.

  • ISO 22301 business continuity management

    Addresses DORA's operational continuity, business impact analysis, and recovery requirements.

  • FCA Operational Resilience (PS21/3)

    UK-specific operational resilience framework with substantial overlap on important business services, impact tolerance, and severe-but-plausible scenario testing.

  • NIS 2 Directive

    EU-wide cybersecurity framework applying to operators of essential services and digital service providers, with overlap on incident reporting and supply chain security.

  • Critical Third Parties (CTP) regime under FSMA 2023

    UK regime targeting systemically important third parties to financial entities, with conceptual alignment to DORA's critical ICT third-party oversight.

  • Cyber Security and Resilience Bill (introduced 12 November 2025)

    UK legislation strengthening cyber resilience obligations across critical sectors, intersecting with DORA-equivalent operational resilience expectations.

Frequently asked

Discuss where this framework fits your programme

Whether your organisation is an EU financial entity preparing to demonstrate DORA compliance, a UK ICT provider facing DORA-compliant contract terms from EU financial customers, or a complex cross-jurisdictional entity navigating overlapping operational resilience obligations, Goldline provides senior practitioner founder-led delivery calibrated to your regulatory exposure and operational complexity.

Book a free 45 minute diagnostic to scope DORA applicability, current operational resilience posture, adjacent regulatory exposure, and engagement structure.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.